CIO Report
AI access overview
At a glance · 17 Sep – 3 Oct 2026Executive summary
Prepared 3 October 2026Generative AI is now a routine work tool at Exhibition St, is blocked at Crown Casino, and nothing in between is checking what goes into it. The FortiGate web-filter log for the Artificial Intelligence Technology category holds 100,000 URL requests between 17 September and 3 October 2026, from 220 endpoints and 86 named staff accounts. ChatGPT alone is half of all requests; Perplexity, which the earlier application-control view did not show at all, is a fifth.
The two sites still run opposite policies. Exhibition St (EXH-FTG-FW01) passed 97,605 requests without inspection. Crown Casino (CRWN-FGT-FW01) blocked all 2,395 of its requests, most of them Microsoft Copilot calls from 27 office PCs and a photo-editing AI app on one iPhone. Over the period Exhibition St devices sent about 1.1 GB to AI services, including 474 MB to ChatGPT, 343 MB to Claude and a single 262 MB upload to claude.ai on 1 October from one PC.
DLP and sensitive-data detection on AI traffic still read zero because no DLP profile is applied to the policies that allow this traffic. The log identifies PCs and, for a tenth of traffic, people, so the organisation can already answer who; it cannot yet answer what. The decision for this quarter is unchanged: sanction a defined set of AI tools estate-wide with inspection on, or block them estate-wide, rather than leaving the answer to depend on which building a person sits in.
Sites in scope
Period highlights
GenAI usage
By application · by day · web-filter logTen AI services were reached in the period; five of them carry 98% of requests. Usage is heavily concentrated: the top 5 endpoints generate 54% of all AI requests and the top 10 generate 76%. Traffic follows the working week, peaking Tuesday to Thursday and falling to near zero on weekends and over the 25 to 27 September long weekend.
Copilot is broad and shallow: 206 endpoints and 86 named users, mostly background calls from Microsoft 365 apps, which is why it is the one AI service seen on nearly every PC. ChatGPT, Claude and Perplexity are narrow and deep: a few dozen PCs, a handful of named users, and tens of thousands of requests each, with 38% of ChatGPT and 55% of Claude requests being POSTs, the method that carries prompts and uploads.
The long tail matters more than its size. Granola (notes.granola.ai) is an AI meeting recorder, Suno generates music, Hugging Face hosts models and datasets, and Meitu is a consumer photo-editing app that phoned home 1,291 times from one iPhone on the Crown Casino network in a single day. None of these are business tools, and none had been visible before this log was pulled.
Policy posture by site
Crown Casino blocks · Exhibition St allowsCrown Casino’s block is a web-filter warning category rather than a hard block, and no user clicked through in the period, so it behaves as a block today. The 27 Crown Casino PCs hitting copilot.cloud.microsoft are Microsoft 365 users whose Office apps call Copilot automatically; the block generates noise and helpdesk friction rather than stopping deliberate use. Nearly all Exhibition St AI traffic rides policy 2 (Corp-Internet-VGCCC), so a single policy change there would cover 98% of the estate’s AI use.
A third managed device, AI-Webview, appears in the device selector but reported no GenAI traffic, and VCGLR_FW_CLUSTER is sitting in Device Manager as an unauthorised device that is not logging at all.
Data-leak risk
DLP coverage · upload volumesFortiAnalyzer reports 0 DLP violations and 0 sensitive-data detections on AI traffic, and the Data Loss Prevention view holds no records at all. Because no DLP profile is applied to the policies that allow GenAI, the zero is an absence of inspection, not an absence of leakage.
What can be measured is volume and direction. Across 10,437 AI sessions, Exhibition St devices sent 1.14 GB to AI services and received 0.91 GB: 474 MB to ChatGPT, 343 MB to Claude, 259 MB to Copilot and 46 MB to Gemini. Sixteen sessions each carried more than 5 MB outbound, the size of a document rather than a question, and one claude.ai session on 1 October from PC VGCCC-P000232 sent 262 MB in a single upload. 36% of all AI requests were POSTs.
The log names the source for most of this traffic: 86 named VCGLR accounts and 136 machine accounts appear in the user field, so the people behind the 262 MB upload and the top ChatGPT and Perplexity users can be identified today without any new logging. That is useful for a conversation; it is not a control. Copilot traffic stays inside the Microsoft 365 tenant only if the licences are Microsoft 365 Copilot rather than the consumer app, which the web filter cannot distinguish. ChatGPT, Claude, Perplexity and Gemini use here is consumer-grade unless someone has bought Team or Enterprise plans, which by default means prompts and uploads may be retained by the provider.
Data sent, by service
Controls to close the gap
Users and devices
Top PCs · all named accountsMost AI traffic is attributed to a PC rather than a person: 90% of requests carry a machine account (host/VGCCC-Pnnnnnn) in the user field and 10% a named VCGLR account, because the browser sessions that generate the bulk of ChatGPT, Perplexity and Claude use are not passing a user identity to the firewall. The 15 PCs below produce 82% of all AI requests; the asset register will say who holds each one.
FortiGuard protection and platform health
As at 21 September 2026As read from FortiAnalyzer on 21 September 2026 (not re-checked against the 3 October log export). The firewalls detected 43.4K threat events in that week, but only 268 were blocked; 43.2K were alert-only, dominated by the blocked-connection signature, Apple Private Relay and Google’s data-saver proxy, which are policy noise rather than attacks. There were no virus incidents, indicators of compromise or FortiSandbox detections, and nothing AI-themed in the threat list.
The last row is the most urgent item in this report and has nothing to do with AI. The FortiAnalyzer GUI at 4.198.125.59 is reachable from the internet and was being password-sprayed while the data was collected. Restricting the GUI to trusted hosts or a VPN, and enabling two-factor for the admin account, should happen this week.
Recommended decisions
Owners and due datesRe-run this report monthly. The three numbers to track are AI requests per site, MB sent to non-Microsoft AI services, and DLP matches on AI traffic once inspection is in place.
Method and sources
Where every figure came fromUsage, policy and data-volume figures come from a FortiAnalyzer web-filter log export for ADOM FSFADOM3-FGT (file FSFADOM3-FGT_wlog_from_2026-09-01 13_04_41_to_2026-10-03 13_04_41), filtered to the Artificial Intelligence Technology category. The export is capped at 100,000 rows, which in practice covers 17 September 10:11 to 3 October 12:58 AEST; 1 to 16 September fell outside the cap. Platform-health figures were read from the FortiAnalyzer GUI (pausefgtfaz01, v8.0.0) on 21 September 2026.
Caveats. A URL request is not a session: Copilot generates many background requests per user, so request counts overstate its deliberate use and understate ChatGPT’s relative to the session view. Endpoint counts are source IPs; named users are distinct values in the log’s user field, excluding machine accounts. Bytes are what the firewall saw at the session level and, without SSL inspection, cannot be split into prompts versus files. 17 September and 3 October are partial days.